# Active Directory perfmon counter in metricbeat

**URL:** <https://discuss.elastic.co/t/active-directory-perfmon-counter-in-metricbeat/329537>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [April 6, 2023, 4:56pm UTC](https://discuss.elastic.co/t/active-directory-perfmon-counter-in-metricbeat/329537 "2023-04-06T16:56:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shaakxuur](https://avatars.discourse-cdn.com/v4/letter/s/ccd318/32.png) [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Post date:** [April 6, 2023, 4:56pm UTC](https://discuss.elastic.co/t/active-directory-perfmon-counter-in-metricbeat/329537/1 "2023-04-06T16:56:37Z")

</div>

Hi!

I have two questions about Active Directory perfmon counters.  
I´ve created some counters based on this article:

> [@Metricbeat Active Directory (AD) performance metrics (perfmon) yaml build](https://discuss.elastic.co/t/metricbeat-active-directory-ad-performance-metrics-perfmon-yaml-build/209687):
>
> I'm looking for a little guidance on how to build out the windows.yml module in Metricbeat. If this is being built out correctly we may need 3-4 lines to ship the Active Directroy perfmon out. The issue that I'm having is that I'm not able to find a lot of specified info on AD perfmon so if anyone has any links that I could be missing that would be appreciated. From my research it seems like these perfmon counters are also under NTDS so I'm not sure how this fits into the syntax as well. I s…

And in this article I have seen then that this syntax no longer exists:

> **[Windows perfmon metricset | Metricbeat Reference \[7.17\] | Elastic](https://www.elastic.co/guide/en/beats/metricbeat/7.17/metricbeat-metricset-windows-perfmon.html)**

Now I'm not sure how to change the old counters to the new format.  
Old:

```auto
- module: windows
  metricsets: [perfmon]
  enabled: true
  period: 30s
  perfmon.ignore_non_existent_counters: true
  perfmon.group_measurements_by_instance: true
  perfmon.queries:
      #NTDS
    - instance_label: "instance.name"
      instance_name: "NTDS"
      measurement_label: "ntds.atq.threads.ldap"
      query: '\DirectoryServices(NTDS)\ATQ Threads LDAP'
    - instance_label: "instance.name"
      instance_name: "NTDS"
      measurement_label: "ntds.atq.threads.total"
      query: '\DirectoryServices(NTDS)\ATQ Threads Total'
    - instance_label: "instance.name"
      instance_name: "NTDS"
      measurement_label: "ntds.ds.directory.reads.sec"
      query: '\DirectoryServices(NTDS)\DS Directory Reads/sec'
    - instance_label: "instance.name"
      instance_name: "NTDS"
      measurement_label: "ntds.ds.threads"
      query: '\DirectoryServices(NTDS)\DS Threads in Use'
    - instance_label: "instance.name"
      instance_name: "NTDS"
      measurement_label: "ntds.ldap.active.threads"
      query: '\DirectoryServices(NTDS)\LDAP Active Threads'
    - instance_label: "instance.name"
      instance_name: "NTDS"
      measurement_label: "ntds.ldap.client.sessions"
      query: '\DirectoryServices(NTDS)\LDAP Client Sessions'
    - instance_label: "instance.name"
      instance_name: "NTDS"
      measurement_label: "ntds.ldap.bind.time"
      query: '\DirectoryServices(NTDS)\LDAP Bind Time'

```

My try:

```auto
- module: windows
  metricsets: [perfmon]
  period: 30s
  perfmon.ignore_non_existent_counters: true
  perfmon.group_measurements_by_instance: true
  perfmon.queries:
  - object: "DirectoryServices"
    Instance: "NTDS"
    counters:
    - name: "ATQ Threads LDAP"
  - object: "DirectoryServices"
    Instance: "NTDS"
    counters:
    - name: "ATQ Threads Total"
  - object: "DirectoryServices"
    Instance: "NTDS"
    counters:
    - name: "DS Directory Reads/sec"
  - object: "DirectoryServices"
    Instance: "NTDS"
    counters:
    - name: "DS Threads in Use"
  - object: "DirectoryServices"
    Instance: "NTDS"
    counters:
    - name: "LDAP Active Threads"
  - object: "DirectoryServices"
    Instance: "NTDS"
    counters:
    - name: "LDAP Client Sessions"
  - object: "DirectoryServices"
    Instance: "NTDS"
    counters:
    - name: "LDAP Bind Time"

```

Is that correct?

Second question:  
How can I see these counters in Elastic/Kibana?

Thanks!!

---

<div class="post-metadata">

**Author:** ![Shaakxuur](https://avatars.discourse-cdn.com/v4/letter/s/ccd318/32.png) [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Post date:** [April 25, 2023, 12:26pm UTC](https://discuss.elastic.co/t/active-directory-perfmon-counter-in-metricbeat/329537/2 "2023-04-25T12:26:30Z")

</div>

No one who can help?  
Is there a good article where the differences are explained?

---

<div class="post-metadata">

**Author:** ![Shaakxuur](https://avatars.discourse-cdn.com/v4/letter/s/ccd318/32.png) [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Post date:** [May 8, 2023, 1:42pm UTC](https://discuss.elastic.co/t/active-directory-perfmon-counter-in-metricbeat/329537/3 "2023-05-08T13:42:51Z")

</div>

Okay  
We will try another way.  
We will create a test system and install the Microsoft System Center environment there (-\> Operation Manager).  
The test version will run for 180 days, if it meets our requirements, then we will pay the license costs.

The ticket / question can be closed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2023, 3:43pm UTC](https://discuss.elastic.co/t/active-directory-perfmon-counter-in-metricbeat/329537/4 "2023-06-05T15:43:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
